Security
Built to protect your data
We protect your data with strong, defense-in-depth security practices, engineered into the platform from day one: tightly scoped access, encryption in transit and at rest, PHI minimized before it ever reaches an AI feature, and a complete audit trail behind every action.
Facility-scoped access
Access is scoped to a single facility. A user in one building never reaches another building's residents or records.
Role-based, function-level authorization
Role-based permissions and function-level authorization are enforced on every data path, so each person reaches only the functions and records their role requires.
Encrypted in transit and at rest
Protected health information (PHI) is encrypted in transit and at rest, so it stays protected wherever it moves and wherever it lives.
A BAA before any PHI
We execute a Business Associate Agreement (BAA) with every facility customer before any protected health information is processed. The BAA governs exactly how PHI is handled.
Comprehensive audit logs
Every access and change is logged with timestamps, user attribution, and change tracking. The same audit trail that backs our reports backs our own accountability.
PHI-minimized AI inputs
AI features receive inputs minimized of PHI: internal identifiers, never names. The model sees only what it needs to do its job.